dnsproxy: Move from plugins to core
[platform/upstream/connman.git] / src / dnsproxy.c
1 /*
2  *
3  *  Connection Manager
4  *
5  *  Copyright (C) 2007-2010  Intel Corporation. All rights reserved.
6  *
7  *  This program is free software; you can redistribute it and/or modify
8  *  it under the terms of the GNU General Public License version 2 as
9  *  published by the Free Software Foundation.
10  *
11  *  This program is distributed in the hope that it will be useful,
12  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
13  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14  *  GNU General Public License for more details.
15  *
16  *  You should have received a copy of the GNU General Public License
17  *  along with this program; if not, write to the Free Software
18  *  Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
19  *
20  */
21
22 #ifdef HAVE_CONFIG_H
23 #include <config.h>
24 #endif
25
26 #include <errno.h>
27 #include <unistd.h>
28 #include <string.h>
29 #include <stdint.h>
30 #include <arpa/inet.h>
31 #include <netinet/in.h>
32 #include <sys/types.h>
33 #include <sys/socket.h>
34 #include <netdb.h>
35
36 #include <glib.h>
37
38 #define CONNMAN_API_SUBJECT_TO_CHANGE
39 #include <connman/ondemand.h>
40
41 #include "connman.h"
42
43 #if __BYTE_ORDER == __LITTLE_ENDIAN
44 struct domain_hdr {
45         uint16_t id;
46         uint8_t rd:1;
47         uint8_t tc:1;
48         uint8_t aa:1;
49         uint8_t opcode:4;
50         uint8_t qr:1;
51         uint8_t rcode:4;
52         uint8_t z:3;
53         uint8_t ra:1;
54         uint16_t qdcount;
55         uint16_t ancount;
56         uint16_t nscount;
57         uint16_t arcount;
58 } __attribute__ ((packed));
59 #elif __BYTE_ORDER == __BIG_ENDIAN
60 struct domain_hdr {
61         uint16_t id;
62         uint8_t qr:1;
63         uint8_t opcode:4;
64         uint8_t aa:1;
65         uint8_t tc:1;
66         uint8_t rd:1;
67         uint8_t ra:1;
68         uint8_t z:3;
69         uint8_t rcode:4;
70         uint16_t qdcount;
71         uint16_t ancount;
72         uint16_t nscount;
73         uint16_t arcount;
74 } __attribute__ ((packed));
75 #else
76 #error "Unknown byte order"
77 #endif
78
79 struct partial_reply {
80         uint16_t len;
81         uint16_t received;
82         unsigned char buf[];
83 };
84
85 struct server_data {
86         char *interface;
87         GList *domains;
88         char *server;
89         int protocol;
90         GIOChannel *channel;
91         guint watch;
92         guint timeout;
93         gboolean enabled;
94         gboolean connected;
95         struct partial_reply *incoming_reply;
96 };
97
98 struct request_data {
99         union {
100                 struct sockaddr_in6 __sin6; /* Only for the length */
101                 struct sockaddr sa;
102         };
103         socklen_t sa_len;
104         int client_sk;
105         int protocol;
106         guint16 srcid;
107         guint16 dstid;
108         guint16 altid;
109         guint timeout;
110         guint watch;
111         guint numserv;
112         guint numresp;
113         gpointer request;
114         gsize request_len;
115         gpointer name;
116         gpointer resp;
117         gsize resplen;
118 };
119
120 static GSList *server_list = NULL;
121 static GSList *request_list = NULL;
122 static GSList *request_pending_list = NULL;
123 static guint16 request_id = 0x0000;
124
125 static GIOChannel *udp_listener_channel = NULL;
126 static guint udp_listener_watch = 0;
127 static GIOChannel *tcp_listener_channel = NULL;
128 static guint tcp_listener_watch = 0;
129
130 static int protocol_offset(int protocol)
131 {
132         switch (protocol) {
133         case IPPROTO_UDP:
134                 return 0;
135
136         case IPPROTO_TCP:
137                 return 2;
138
139         default:
140                 return -EINVAL;
141         }
142
143 }
144
145 static struct request_data *find_request(guint16 id)
146 {
147         GSList *list;
148
149         for (list = request_list; list; list = list->next) {
150                 struct request_data *req = list->data;
151
152                 if (req->dstid == id || req->altid == id)
153                         return req;
154         }
155
156         return NULL;
157 }
158
159 static struct server_data *find_server(const char *interface,
160                                         const char *server,
161                                                 int protocol)
162 {
163         GSList *list;
164
165         DBG("interface %s server %s", interface, server);
166
167         for (list = server_list; list; list = list->next) {
168                 struct server_data *data = list->data;
169
170                 if (data->interface == NULL || data->server == NULL)
171                         continue;
172
173                 if (g_str_equal(data->interface, interface) == TRUE &&
174                                 g_str_equal(data->server, server) == TRUE &&
175                                 data->protocol == protocol)
176                         return data;
177         }
178
179         return NULL;
180 }
181
182
183 static void send_response(int sk, unsigned char *buf, int len,
184                                 const struct sockaddr *to, socklen_t tolen,
185                                 int protocol)
186 {
187         struct domain_hdr *hdr;
188         int err, offset = protocol_offset(protocol);
189
190         DBG("");
191
192         if (offset < 0)
193                 return;
194
195         if (len < 12)
196                 return;
197
198         hdr = (void*) (buf + offset);
199
200         DBG("id 0x%04x qr %d opcode %d", hdr->id, hdr->qr, hdr->opcode);
201
202         hdr->qr = 1;
203         hdr->rcode = 2;
204
205         hdr->ancount = 0;
206         hdr->nscount = 0;
207         hdr->arcount = 0;
208
209         err = sendto(sk, buf, len, 0, to, tolen);
210 }
211
212 static gboolean request_timeout(gpointer user_data)
213 {
214         struct request_data *req = user_data;
215
216         DBG("id 0x%04x", req->srcid);
217
218         if (req == NULL)
219                 return FALSE;
220
221         request_list = g_slist_remove(request_list, req);
222         req->numserv--;
223
224         if (req->resplen > 0 && req->resp != NULL) {
225                 int sk, err;
226
227                 sk = g_io_channel_unix_get_fd(udp_listener_channel);
228
229                 err = sendto(sk, req->resp, req->resplen, 0,
230                              &req->sa, req->sa_len);
231         } else if (req->request && req->numserv == 0) {
232                 struct domain_hdr *hdr;
233
234                 if (req->protocol == IPPROTO_TCP) {
235                         hdr = (void *) (req->request + 2);
236                         hdr->id = req->srcid;
237                         send_response(req->client_sk, req->request,
238                                         req->request_len, NULL, 0, IPPROTO_TCP);
239
240                 } else if (req->protocol == IPPROTO_UDP) {
241                         int sk;
242
243                         hdr = (void *) (req->request);
244                         hdr->id = req->srcid;
245                         sk = g_io_channel_unix_get_fd(udp_listener_channel);
246                         send_response(sk, req->request, req->request_len,
247                                       &req->sa, req->sa_len, IPPROTO_UDP);
248                 }
249         }
250
251         g_free(req->resp);
252         g_free(req);
253
254         return FALSE;
255 }
256
257 static int append_query(unsigned char *buf, unsigned int size,
258                                 const char *query, const char *domain)
259 {
260         unsigned char *ptr = buf;
261         char *offset;
262
263         DBG("query %s domain %s", query, domain);
264
265         offset = (char *) query;
266         while (offset != NULL) {
267                 char *tmp;
268
269                 tmp = strchr(offset, '.');
270                 if (tmp == NULL) {
271                         if (strlen(offset) == 0)
272                                 break;
273                         *ptr = strlen(offset);
274                         memcpy(ptr + 1, offset, strlen(offset));
275                         ptr += strlen(offset) + 1;
276                         break;
277                 }
278
279                 *ptr = tmp - offset;
280                 memcpy(ptr + 1, offset, tmp - offset);
281                 ptr += tmp - offset + 1;
282
283                 offset = tmp + 1;
284         }
285
286         offset = (char *) domain;
287         while (offset != NULL) {
288                 char *tmp;
289
290                 tmp = strchr(offset, '.');
291                 if (tmp == NULL) {
292                         if (strlen(offset) == 0)
293                                 break;
294                         *ptr = strlen(offset);
295                         memcpy(ptr + 1, offset, strlen(offset));
296                         ptr += strlen(offset) + 1;
297                         break;
298                 }
299
300                 *ptr = tmp - offset;
301                 memcpy(ptr + 1, offset, tmp - offset);
302                 ptr += tmp - offset + 1;
303
304                 offset = tmp + 1;
305         }
306
307         *ptr++ = 0x00;
308
309         return ptr - buf;
310 }
311
312 static int ns_resolv(struct server_data *server, struct request_data *req,
313                                 gpointer request, gpointer name)
314 {
315         GList *list;
316         int sk, err;
317
318         sk = g_io_channel_unix_get_fd(server->channel);
319
320         err = send(sk, request, req->request_len, 0);
321
322         req->numserv++;
323
324         for (list = server->domains; list; list = list->next) {
325                 char *domain;
326                 unsigned char alt[1024];
327                 struct domain_hdr *hdr = (void *) &alt;
328                 int altlen, domlen, offset;
329
330                 domain = list->data;
331
332                 if (domain == NULL)
333                         continue;
334
335                 offset = protocol_offset(server->protocol);
336                 if (offset < 0)
337                         return offset;
338
339                 domlen = strlen(domain) + 1;
340                 if (domlen < 5)
341                         return -EINVAL;
342
343                 alt[offset] = req->altid & 0xff;
344                 alt[offset + 1] = req->altid >> 8;
345
346                 memcpy(alt + offset + 2, request + offset + 2, 10);
347                 hdr->qdcount = htons(1);
348
349                 altlen = append_query(alt + offset + 12, sizeof(alt) - 12,
350                                         name, domain);
351                 if (altlen < 0)
352                         return -EINVAL;
353
354                 altlen += 12;
355
356                 memcpy(alt + offset + altlen,
357                         request + offset + altlen - domlen,
358                                 req->request_len - altlen + domlen);
359
360                 if (server->protocol == IPPROTO_TCP) {
361                         int req_len = req->request_len + domlen - 1;
362
363                         alt[0] = (req_len >> 8) & 0xff;
364                         alt[1] = req_len & 0xff;
365                 }
366
367                 err = send(sk, alt, req->request_len + domlen + 1, 0);
368
369                 req->numserv++;
370         }
371
372         return 0;
373 }
374
375 static int forward_dns_reply(unsigned char *reply, int reply_len, int protocol)
376 {
377         struct domain_hdr *hdr;
378         struct request_data *req;
379         int dns_id, sk, err, offset = protocol_offset(protocol);
380
381         if (offset < 0)
382                 return offset;
383
384         hdr = (void *)(reply + offset);
385         dns_id = reply[offset] | reply[offset + 1] << 8;
386
387         DBG("Received %d bytes (id 0x%04x)", reply_len, dns_id);
388
389         req = find_request(dns_id);
390         if (req == NULL)
391                 return -EINVAL;
392
393         DBG("id 0x%04x rcode %d", hdr->id, hdr->rcode);
394
395         reply[offset] = req->srcid & 0xff;
396         reply[offset + 1] = req->srcid >> 8;
397
398         req->numresp++;
399
400         if (hdr->rcode == 0 || req->resp == NULL) {
401                 g_free(req->resp);
402                 req->resplen = 0;
403
404                 req->resp = g_try_malloc(reply_len);
405                 if (req->resp == NULL)
406                         return -ENOMEM;
407
408                 memcpy(req->resp, reply, reply_len);
409                 req->resplen = reply_len;
410         }
411
412         if (hdr->rcode > 0 && req->numresp < req->numserv)
413                 return -EINVAL;
414
415         if (req->timeout > 0)
416                 g_source_remove(req->timeout);
417
418         request_list = g_slist_remove(request_list, req);
419
420         if (protocol == IPPROTO_UDP) {
421                 sk = g_io_channel_unix_get_fd(udp_listener_channel);
422                 err = sendto(sk, req->resp, req->resplen, 0,
423                              &req->sa, req->sa_len);
424         } else {
425                 sk = req->client_sk;
426                 err = send(sk, req->resp, req->resplen, 0);
427                 close(sk);
428         }
429
430         g_free(req->resp);
431         g_free(req);
432
433         return err;
434 }
435
436 static void destroy_server(struct server_data *server)
437 {
438         GList *list;
439
440         DBG("interface %s server %s", server->interface, server->server);
441
442         server_list = g_slist_remove(server_list, server);
443
444         if (server->watch > 0)
445                 g_source_remove(server->watch);
446
447         if (server->timeout > 0)
448                 g_source_remove(server->timeout);
449
450         g_io_channel_unref(server->channel);
451
452         if (server->protocol == IPPROTO_UDP)
453                 connman_info("Removing DNS server %s", server->server);
454
455         g_free(server->incoming_reply);
456         g_free(server->server);
457         for (list = server->domains; list; list = list->next) {
458                 char *domain = list->data;
459
460                 server->domains = g_list_remove(server->domains, domain);
461                 g_free(domain);
462         }
463         g_free(server->interface);
464         g_free(server);
465 }
466
467 static gboolean udp_server_event(GIOChannel *channel, GIOCondition condition,
468                                                         gpointer user_data)
469 {
470         unsigned char buf[4096];
471         int sk, err, len;
472
473         if (condition & (G_IO_NVAL | G_IO_ERR | G_IO_HUP)) {
474                 struct server_data *data = user_data;
475
476                 connman_error("Error with UDP server %s", data->server);
477                 data->watch = 0;
478                 return FALSE;
479         }
480
481         sk = g_io_channel_unix_get_fd(channel);
482
483         len = recv(sk, buf, sizeof(buf), 0);
484         if (len < 12)
485                 return TRUE;
486
487         err = forward_dns_reply(buf, len, IPPROTO_UDP);
488
489         return TRUE;
490 }
491
492 static gboolean tcp_server_event(GIOChannel *channel, GIOCondition condition,
493                                                         gpointer user_data)
494 {
495         int sk;
496         struct server_data *server = user_data;
497
498         sk = g_io_channel_unix_get_fd(channel);
499         if (sk == 0)
500                 return FALSE;
501
502         if (condition & (G_IO_NVAL | G_IO_ERR | G_IO_HUP)) {
503                 GSList *list;
504         hangup:
505                 DBG("TCP server channel closed");
506
507                 /*
508                  * Discard any partial response which is buffered; better
509                  * to get a proper response from a working server.
510                  */
511                 g_free(server->incoming_reply);
512                 server->incoming_reply = NULL;
513
514                 for (list = request_list; list; list = list->next) {
515                         struct request_data *req = list->data;
516                         struct domain_hdr *hdr;
517
518                         if (req->protocol == IPPROTO_UDP)
519                                 continue;
520
521                         if (req->request == NULL)
522                                 continue;
523
524                         /*
525                          * If we're not waiting for any further response
526                          * from another name server, then we send an error
527                          * response to the client.
528                          */
529                         if (req->numserv && --(req->numserv))
530                                 continue;
531
532                         hdr = (void *) (req->request + 2);
533                         hdr->id = req->srcid;
534                         send_response(req->client_sk, req->request,
535                                         req->request_len, NULL, 0, IPPROTO_TCP);
536
537                         request_list = g_slist_remove(request_list, req);
538                 }
539
540                 destroy_server(server);
541
542                 return FALSE;
543         }
544
545         if ((condition & G_IO_OUT) && !server->connected) {
546                 GSList *list;
547                 GList *domains;
548                 struct server_data *udp_server;
549
550                 udp_server = find_server(server->interface, server->server,
551                                                                 IPPROTO_UDP);
552                 if (udp_server != NULL) {
553                         for (domains = udp_server->domains; domains;
554                                                 domains = domains->next) {
555                                 char *dom = domains->data;
556
557                                 DBG("Adding domain %s to %s",
558                                                 dom, server->server);
559
560                                 server->domains = g_list_append(server->domains,
561                                                                 g_strdup(dom));
562                         }
563                 }
564
565                 server->connected = TRUE;
566                 server_list = g_slist_append(server_list, server);
567
568                 if (server->timeout > 0) {
569                         g_source_remove(server->timeout);
570                         server->timeout = 0;
571                 }
572
573                 for (list = request_list; list; list = list->next) {
574                         struct request_data *req = list->data;
575
576                         if (req->protocol == IPPROTO_UDP)
577                                 continue;
578
579                         DBG("Sending req %s over TCP", (char *)req->name);
580
581                         if (req->timeout > 0)
582                                 g_source_remove(req->timeout);
583
584                         req->timeout = g_timeout_add_seconds(30,
585                                                 request_timeout, req);
586                         ns_resolv(server, req, req->request, req->name);
587                 }
588
589         } else if (condition & G_IO_IN) {
590                 struct partial_reply *reply = server->incoming_reply;
591                 int bytes_recv;
592
593                 if (!reply) {
594                         unsigned char reply_len_buf[2];
595                         uint16_t reply_len;
596
597                         bytes_recv = recv(sk, reply_len_buf, 2, MSG_PEEK);
598                         if (!bytes_recv) {
599                                 goto hangup;
600                         } else if (bytes_recv < 0) {
601                                 if (errno == EAGAIN || errno == EWOULDBLOCK)
602                                         return TRUE;
603
604                                 connman_error("DNS proxy error %s",
605                                                 strerror(errno));
606                                 goto hangup;
607                         } else if (bytes_recv < 2)
608                                 return TRUE;
609
610                         reply_len = reply_len_buf[1] | reply_len_buf[0] << 8;
611                         reply_len += 2;
612
613                         DBG("TCP reply %d bytes", reply_len);
614
615                         reply = g_try_malloc(sizeof(*reply) + reply_len + 2);
616                         if (!reply)
617                                 return TRUE;
618
619                         reply->len = reply_len;
620                         reply->received = 0;
621
622                         server->incoming_reply = reply;
623                 }
624
625                 while (reply->received < reply->len) {
626                         bytes_recv = recv(sk, reply->buf + reply->received,
627                                         reply->len - reply->received, 0);
628                         if (!bytes_recv) {
629                                 connman_error("DNS proxy TCP disconnect");
630                                 break;
631                         } else if (bytes_recv < 0) {
632                                 if (errno == EAGAIN || errno == EWOULDBLOCK)
633                                         return TRUE;
634
635                                 connman_error("DNS proxy error %s",
636                                                 strerror(errno));
637                                 break;
638                         }
639                         reply->received += bytes_recv;
640                 }
641
642                 forward_dns_reply(reply->buf, reply->received, IPPROTO_TCP);
643
644                 g_free(reply);
645                 server->incoming_reply = NULL;
646
647                 destroy_server(server);
648
649                 return FALSE;
650         }
651
652         return TRUE;
653 }
654
655 static gboolean tcp_idle_timeout(gpointer user_data)
656 {
657         struct server_data *server = user_data;
658
659         DBG("");
660
661         if (server == NULL)
662                 return FALSE;
663
664         destroy_server(server);
665
666         return FALSE;
667 }
668
669 static struct server_data *create_server(const char *interface,
670                                         const char *domain, const char *server,
671                                         int protocol)
672 {
673         struct addrinfo hints, *rp;
674         struct server_data *data;
675         int sk, ret;
676
677         DBG("interface %s server %s", interface, server);
678
679         memset(&hints, 0, sizeof(hints));
680
681         switch (protocol) {
682         case IPPROTO_UDP:
683                 hints.ai_socktype = SOCK_DGRAM;
684                 break;
685
686         case IPPROTO_TCP:
687                 hints.ai_socktype = SOCK_STREAM;
688                 break;
689
690         default:
691                 return NULL;
692         }
693         hints.ai_family = AF_UNSPEC;
694         hints.ai_flags = AI_PASSIVE | AI_NUMERICSERV | AI_NUMERICHOST;
695
696         ret = getaddrinfo(server, "53", &hints, &rp);
697         if (ret) {
698                 connman_error("Failed to parse server %s address: %s\n",
699                               server, gai_strerror(ret));
700                 return NULL;
701         }
702         /* Do not blindly copy this code elsewhere; it doesn't loop over the
703            results using ->ai_next as it should. That's OK in *this* case
704            because it was a numeric lookup; we *know* there's only one. */
705
706         sk = socket(rp->ai_family, rp->ai_socktype, rp->ai_protocol);
707         if (sk < 0) {
708                 connman_error("Failed to create server %s socket", server);
709                 freeaddrinfo(rp);
710                 return NULL;
711         }
712
713         if (interface != NULL) {
714                 if (setsockopt(sk, SOL_SOCKET, SO_BINDTODEVICE,
715                                 interface, strlen(interface) + 1) < 0) {
716                         connman_error("Failed to bind server %s "
717                                                 "to interface %s",
718                                                         server, interface);
719                         freeaddrinfo(rp);
720                         close(sk);
721                         return NULL;
722                 }
723         }
724
725         data = g_try_new0(struct server_data, 1);
726         if (data == NULL) {
727                 connman_error("Failed to allocate server %s data", server);
728                 freeaddrinfo(rp);
729                 close(sk);
730                 return NULL;
731         }
732
733         data->channel = g_io_channel_unix_new(sk);
734         if (data->channel == NULL) {
735                 connman_error("Failed to create server %s channel", server);
736                 freeaddrinfo(rp);
737                 close(sk);
738                 g_free(data);
739                 return NULL;
740         }
741
742         g_io_channel_set_close_on_unref(data->channel, TRUE);
743
744         if (protocol == IPPROTO_TCP) {
745                 g_io_channel_set_flags(data->channel, G_IO_FLAG_NONBLOCK, NULL);
746                 data->watch = g_io_add_watch(data->channel,
747                         G_IO_OUT | G_IO_IN | G_IO_HUP | G_IO_NVAL | G_IO_ERR,
748                                                 tcp_server_event, data);
749                 data->timeout = g_timeout_add_seconds(30, tcp_idle_timeout,
750                                                                 data);
751         } else
752                 data->watch = g_io_add_watch(data->channel,
753                         G_IO_IN | G_IO_NVAL | G_IO_ERR | G_IO_HUP,
754                                                 udp_server_event, data);
755
756         data->interface = g_strdup(interface);
757         if (domain)
758                 data->domains = g_list_append(data->domains, g_strdup(domain));
759         data->server = g_strdup(server);
760         data->protocol = protocol;
761
762         ret = connect(sk, rp->ai_addr, rp->ai_addrlen);
763         freeaddrinfo(rp);
764         if (ret < 0) {
765                 if ((protocol == IPPROTO_TCP && errno != EINPROGRESS) ||
766                                 protocol == IPPROTO_UDP) {
767                         GList *list;
768
769                         connman_error("Failed to connect to server %s", server);
770                         if (data->watch > 0)
771                                 g_source_remove(data->watch);
772                         if (data->timeout > 0)
773                                 g_source_remove(data->timeout);
774
775                         g_io_channel_unref(data->channel);
776                         close(sk);
777
778                         g_free(data->server);
779                         g_free(data->interface);
780                         for (list = data->domains; list; list = list->next) {
781                                 char *domain = list->data;
782
783                                 data->domains = g_list_remove(data->domains,
784                                                                         domain);
785                                 g_free(domain);
786                         }
787                         g_free(data);
788                         return NULL;
789                 }
790         }
791
792         if (protocol == IPPROTO_UDP) {
793                 /* Enable new servers by default */
794                 data->enabled = TRUE;
795                 connman_info("Adding DNS server %s", data->server);
796
797                 server_list = g_slist_append(server_list, data);
798
799                 return data;
800         }
801
802         return NULL;
803 }
804
805 static gboolean resolv(struct request_data *req,
806                                 gpointer request, gpointer name)
807 {
808         GSList *list;
809
810         for (list = server_list; list; list = list->next) {
811                 struct server_data *data = list->data;
812
813                 DBG("server %s enabled %d", data->server, data->enabled);
814
815                 if (data->enabled == FALSE)
816                         continue;
817
818                 if (data->watch == 0 && data->protocol == IPPROTO_UDP)
819                         data->watch = g_io_add_watch(data->channel,
820                                 G_IO_IN | G_IO_NVAL | G_IO_ERR | G_IO_HUP,
821                                                 udp_server_event, data);
822
823                 if (ns_resolv(data, req, request, name) < 0)
824                         continue;
825         }
826
827         return TRUE;
828 }
829
830 static void append_domain(const char *interface, const char *domain)
831 {
832         GSList *list;
833
834         DBG("interface %s domain %s", interface, domain);
835
836         for (list = server_list; list; list = list->next) {
837                 struct server_data *data = list->data;
838                 GList *dom_list;
839                 char *dom;
840                 gboolean dom_found = FALSE;
841
842                 if (data->interface == NULL)
843                         continue;
844
845                 if (g_str_equal(data->interface, interface) == FALSE)
846                         continue;
847
848                 for (dom_list = data->domains; dom_list; dom_list = dom_list->next) {
849                         dom = dom_list->data;
850
851                         if (g_str_equal(dom, domain)) {
852                                 dom_found = TRUE;
853                                 break;
854                         }
855                 }
856
857                 if (dom_found == FALSE)
858                         data->domains = g_list_append(data->domains, g_strdup(domain));
859         }
860 }
861
862 static int dnsproxy_append(const char *interface, const char *domain,
863                                                         const char *server)
864 {
865         struct server_data *data;
866
867         DBG("interface %s server %s", interface, server);
868
869         if (server == NULL && domain == NULL)
870                 return -EINVAL;
871
872         if (server == NULL) {
873                 append_domain(interface, domain);
874
875                 return 0;
876         }
877
878         if (g_str_equal(server, "127.0.0.1") == TRUE)
879                 return -ENODEV;
880
881         data = find_server(interface, server, IPPROTO_UDP);
882         if (data != NULL) {
883                 append_domain(interface, domain);
884                 return 0;
885         }
886
887         data = create_server(interface, domain, server, IPPROTO_UDP);
888         if (data == NULL)
889                 return -EIO;
890
891         return 0;
892 }
893
894 static void remove_server(const char *interface, const char *domain,
895                         const char *server, int protocol)
896 {
897         struct server_data *data;
898
899         data = find_server(interface, server, protocol);
900         if (data == NULL)
901                 return;
902
903         destroy_server(data);
904 }
905
906 static int dnsproxy_remove(const char *interface, const char *domain,
907                                                         const char *server)
908 {
909         DBG("interface %s server %s", interface, server);
910
911         if (server == NULL)
912                 return -EINVAL;
913
914         if (g_str_equal(server, "127.0.0.1") == TRUE)
915                 return -ENODEV;
916
917         remove_server(interface, domain, server, IPPROTO_UDP);
918         remove_server(interface, domain, server, IPPROTO_TCP);
919
920         return 0;
921 }
922
923 static void dnsproxy_flush(void)
924 {
925         GSList *list;
926
927         list = request_pending_list;
928         while (list) {
929                 struct request_data *req = list->data;
930
931                 list = list->next;
932
933                 request_pending_list =
934                                 g_slist_remove(request_pending_list, req);
935                 resolv(req, req->request, req->name);
936                 g_free(req->request);
937                 g_free(req->name);
938         }
939 }
940
941 static struct connman_resolver dnsproxy_resolver = {
942         .name           = "dnsproxy",
943         .priority       = CONNMAN_RESOLVER_PRIORITY_HIGH,
944         .append         = dnsproxy_append,
945         .remove         = dnsproxy_remove,
946         .flush          = dnsproxy_flush,
947 };
948
949 static void dnsproxy_offline_mode(connman_bool_t enabled)
950 {
951         GSList *list;
952
953         DBG("enabled %d", enabled);
954
955         for (list = server_list; list; list = list->next) {
956                 struct server_data *data = list->data;
957
958                 if (enabled == FALSE) {
959                         connman_info("Enabling DNS server %s", data->server);
960                         data->enabled = TRUE;
961                 } else {
962                         connman_info("Disabling DNS server %s", data->server);
963                         data->enabled = FALSE;
964                 }
965         }
966 }
967
968 static void dnsproxy_default_changed(struct connman_service *service)
969 {
970         GSList *list;
971         char *interface;
972
973         DBG("service %p", service);
974
975         if (service == NULL) {
976                 /* When no services are active, then disable DNS proxying */
977                 dnsproxy_offline_mode(TRUE);
978                 return;
979         }
980
981         interface = connman_service_get_interface(service);
982         if (interface == NULL)
983                 return;
984
985         for (list = server_list; list; list = list->next) {
986                 struct server_data *data = list->data;
987
988                 if (g_strcmp0(data->interface, interface) == 0) {
989                         connman_info("Enabling DNS server %s", data->server);
990                         data->enabled = TRUE;
991                 } else {
992                         connman_info("Disabling DNS server %s", data->server);
993                         data->enabled = FALSE;
994                 }
995         }
996
997         g_free(interface);
998 }
999
1000 static struct connman_notifier dnsproxy_notifier = {
1001         .name                   = "dnsproxy",
1002         .default_changed        = dnsproxy_default_changed,
1003         .offline_mode           = dnsproxy_offline_mode,
1004 };
1005
1006 static unsigned char opt_edns0_type[2] = { 0x00, 0x29 };
1007
1008 static int parse_request(unsigned char *buf, int len,
1009                                         char *name, unsigned int size)
1010 {
1011         struct domain_hdr *hdr = (void *) buf;
1012         uint16_t qdcount = ntohs(hdr->qdcount);
1013         uint16_t arcount = ntohs(hdr->arcount);
1014         unsigned char *ptr;
1015         char *last_label = NULL;
1016         unsigned int remain, used = 0;
1017
1018         if (len < 12)
1019                 return -EINVAL;
1020
1021         DBG("id 0x%04x qr %d opcode %d qdcount %d arcount %d",
1022                                         hdr->id, hdr->qr, hdr->opcode,
1023                                                         qdcount, arcount);
1024
1025         if (hdr->qr != 0 || qdcount != 1)
1026                 return -EINVAL;
1027
1028         memset(name, 0, size);
1029
1030         ptr = buf + sizeof(struct domain_hdr);
1031         remain = len - sizeof(struct domain_hdr);
1032
1033         while (remain > 0) {
1034                 uint8_t len = *ptr;
1035
1036                 if (len == 0x00) {
1037                         last_label = (char *) (ptr + 1);
1038                         break;
1039                 }
1040
1041                 if (used + len + 1 > size)
1042                         return -ENOBUFS;
1043
1044                 strncat(name, (char *) (ptr + 1), len);
1045                 strcat(name, ".");
1046
1047                 used += len + 1;
1048
1049                 ptr += len + 1;
1050                 remain -= len + 1;
1051         }
1052
1053         if (last_label && arcount && remain >= 9 && last_label[4] == 0 &&
1054                                 !memcmp(last_label + 5, opt_edns0_type, 2)) {
1055                 uint16_t edns0_bufsize;
1056
1057                 edns0_bufsize = last_label[7] << 8 | last_label[8];
1058
1059                 DBG("EDNS0 buffer size %u", edns0_bufsize);
1060
1061                 /* This is an evil hack until full TCP support has been
1062                  * implemented.
1063                  *
1064                  * Somtimes the EDNS0 request gets send with a too-small
1065                  * buffer size. Since glibc doesn't seem to crash when it
1066                  * gets a response biffer then it requested, just bump
1067                  * the buffer size up to 4KiB.
1068                  */
1069                 if (edns0_bufsize < 0x1000) {
1070                         last_label[7] = 0x10;
1071                         last_label[8] = 0x00;
1072                 }
1073         }
1074
1075         DBG("query %s", name);
1076
1077         return 0;
1078 }
1079
1080 static gboolean tcp_listener_event(GIOChannel *channel, GIOCondition condition,
1081                                                         gpointer user_data)
1082 {
1083         unsigned char buf[768];
1084         char query[512];
1085         struct request_data *req;
1086         struct server_data *server;
1087         int sk, client_sk, len, err;
1088         struct sockaddr_in6 client_addr;
1089         socklen_t client_addr_len = sizeof(client_addr);
1090         GSList *list;
1091
1092         DBG("condition 0x%x", condition);
1093
1094         if (condition & (G_IO_NVAL | G_IO_ERR | G_IO_HUP)) {
1095                 if (tcp_listener_watch > 0)
1096                         g_source_remove(tcp_listener_watch);
1097                 tcp_listener_watch = 0;
1098
1099                 connman_error("Error with TCP listener channel");
1100
1101                 return FALSE;
1102         }
1103
1104         sk = g_io_channel_unix_get_fd(channel);
1105
1106         client_sk = accept(sk, (void *)&client_addr, &client_addr_len);
1107         if (client_sk < 0) {
1108                 connman_error("Accept failure on TCP listener");
1109                 tcp_listener_watch = 0;
1110                 return FALSE;
1111         }
1112
1113         len = recv(client_sk, buf, sizeof(buf), 0);
1114         if (len < 2)
1115                 return TRUE;
1116
1117         DBG("Received %d bytes (id 0x%04x)", len, buf[2] | buf[3] << 8);
1118
1119         err = parse_request(buf + 2, len - 2, query, sizeof(query));
1120         if (err < 0 || (g_slist_length(server_list) == 0 &&
1121                                 connman_ondemand_connected())) {
1122                 send_response(client_sk, buf, len, NULL, 0, IPPROTO_TCP);
1123                 return TRUE;
1124         }
1125
1126         req = g_try_new0(struct request_data, 1);
1127         if (req == NULL)
1128                 return TRUE;
1129
1130         memcpy(&req->sa, &client_addr, client_addr_len);
1131         req->sa_len = client_addr_len;
1132         req->client_sk = client_sk;
1133         req->protocol = IPPROTO_TCP;
1134
1135         request_id += 2;
1136         if (request_id == 0x0000 || request_id == 0xffff)
1137                 request_id += 2;
1138
1139         req->srcid = buf[2] | (buf[3] << 8);
1140         req->dstid = request_id;
1141         req->altid = request_id + 1;
1142         req->request_len = len;
1143
1144         buf[2] = req->dstid & 0xff;
1145         buf[3] = req->dstid >> 8;
1146
1147         req->numserv = 0;
1148         request_list = g_slist_append(request_list, req);
1149
1150         for (list = server_list; list; list = list->next) {
1151                 struct server_data *data = list->data;
1152                 GList *domains;
1153
1154                 if (data->protocol != IPPROTO_UDP || data->enabled == FALSE)
1155                         continue;
1156
1157                 server = create_server(data->interface, NULL,
1158                                         data->server, IPPROTO_TCP);
1159
1160                 /*
1161                  * If server is NULL, we're not connected yet.
1162                  * Copy the relevant buffers and continue with
1163                  * the next nameserver.
1164                  * The request will actually be sent once we're
1165                  * properly connected over TCP to this nameserver.
1166                  */
1167                 if (server == NULL) {
1168                         req->request = g_try_malloc0(req->request_len);
1169                         if (req->request == NULL)
1170                                 return TRUE;
1171
1172                         memcpy(req->request, buf, req->request_len);
1173
1174                         req->name = g_try_malloc0(sizeof(query));
1175                         if (req->name == NULL) {
1176                                 g_free(req->request);
1177                                 return TRUE;
1178                         }
1179                         memcpy(req->name, query, sizeof(query));
1180
1181                         continue;
1182                 }
1183
1184                 if (req->timeout > 0)
1185                         g_source_remove(req->timeout);
1186
1187                 for (domains = data->domains; domains; domains = domains->next) {
1188                         char *dom = domains->data;
1189
1190                         DBG("Adding domain %s to %s", dom, server->server);
1191
1192                         server->domains = g_list_append(server->domains,
1193                                                 g_strdup(dom));
1194                 }
1195
1196                 req->timeout = g_timeout_add_seconds(30, request_timeout, req);
1197                 ns_resolv(server, req, buf, query);
1198         }
1199
1200         return TRUE;
1201 }
1202
1203 static gboolean udp_listener_event(GIOChannel *channel, GIOCondition condition,
1204                                                         gpointer user_data)
1205 {
1206         unsigned char buf[768];
1207         char query[512];
1208         struct request_data *req;
1209         struct sockaddr_in6 client_addr;
1210         socklen_t client_addr_len = sizeof(client_addr);
1211         int sk, err, len;
1212
1213         if (condition & (G_IO_NVAL | G_IO_ERR | G_IO_HUP)) {
1214                 connman_error("Error with UDP listener channel");
1215                 udp_listener_watch = 0;
1216                 return FALSE;
1217         }
1218
1219         sk = g_io_channel_unix_get_fd(channel);
1220
1221         memset(&client_addr, 0, client_addr_len);
1222         len = recvfrom(sk, buf, sizeof(buf), 0, (void *)&client_addr,
1223                        &client_addr_len);
1224         if (len < 2)
1225                 return TRUE;
1226
1227         DBG("Received %d bytes (id 0x%04x)", len, buf[0] | buf[1] << 8);
1228
1229         err = parse_request(buf, len, query, sizeof(query));
1230         if (err < 0 || (g_slist_length(server_list) == 0 &&
1231                                 connman_ondemand_connected())) {
1232                 send_response(sk, buf, len, (void *)&client_addr,
1233                               client_addr_len, IPPROTO_UDP);
1234                 return TRUE;
1235         }
1236
1237         req = g_try_new0(struct request_data, 1);
1238         if (req == NULL)
1239                 return TRUE;
1240
1241         memcpy(&req->sa, &client_addr, client_addr_len);
1242         req->sa_len = client_addr_len;
1243         req->client_sk = 0;
1244         req->protocol = IPPROTO_UDP;
1245
1246         request_id += 2;
1247         if (request_id == 0x0000 || request_id == 0xffff)
1248                 request_id += 2;
1249
1250         req->srcid = buf[0] | (buf[1] << 8);
1251         req->dstid = request_id;
1252         req->altid = request_id + 1;
1253         req->request_len = len;
1254
1255         buf[0] = req->dstid & 0xff;
1256         buf[1] = req->dstid >> 8;
1257
1258         if (!connman_ondemand_connected()) {
1259                 DBG("Starting on demand connection");
1260                 /*
1261                  * We're not connected, let's queue the request and start
1262                  * an on-demand connection.
1263                  */
1264                 req->request = g_try_malloc0(req->request_len);
1265                 if (req->request == NULL)
1266                         return TRUE;
1267
1268                 memcpy(req->request, buf, req->request_len);
1269
1270                 req->name = g_try_malloc0(sizeof(query));
1271                 if (req->name == NULL) {
1272                         g_free(req->request);
1273                         return TRUE;
1274                 }
1275                 memcpy(req->name, query, sizeof(query));
1276
1277                 request_pending_list = g_slist_append(request_pending_list,
1278                                                                         req);
1279
1280                 connman_ondemand_start("", 300);
1281
1282                 return TRUE;
1283         }
1284
1285
1286         req->numserv = 0;
1287         req->timeout = g_timeout_add_seconds(5, request_timeout, req);
1288         request_list = g_slist_append(request_list, req);
1289
1290         return resolv(req, buf, query);
1291 }
1292
1293 static int create_dns_listener(int protocol)
1294 {
1295         GIOChannel *channel;
1296         const char *ifname = "lo", *proto;
1297         union {
1298                 struct sockaddr sa;
1299                 struct sockaddr_in6 sin6;
1300                 struct sockaddr_in sin;
1301         } s;
1302         socklen_t slen;
1303         int sk, type, v6only = 0;
1304         int family = AF_INET6;
1305
1306         DBG("");
1307
1308         switch (protocol) {
1309         case IPPROTO_UDP:
1310                 proto = "UDP";
1311                 type = SOCK_DGRAM;
1312                 break;
1313
1314         case IPPROTO_TCP:
1315                 proto = "TCP";
1316                 type = SOCK_STREAM;
1317                 break;
1318
1319         default:
1320                 return -EINVAL;
1321         }
1322
1323         sk = socket(family, type, protocol);
1324         if (sk < 0 && family == AF_INET6 && errno == EAFNOSUPPORT) {
1325                 connman_error("No IPv6 support; DNS proxy listening only on Legacy IP");
1326                 family = AF_INET;
1327                 sk = socket(family, type, protocol);
1328         }
1329         if (sk < 0) {
1330                 connman_error("Failed to create %s listener socket", proto);
1331                 return -EIO;
1332         }
1333
1334         if (setsockopt(sk, SOL_SOCKET, SO_BINDTODEVICE,
1335                                         ifname, strlen(ifname) + 1) < 0) {
1336                 connman_error("Failed to bind %s listener interface", proto);
1337                 close(sk);
1338                 return -EIO;
1339         }
1340         /* Ensure it accepts Legacy IP connections too */
1341         if (family == AF_INET6 &&
1342             setsockopt(sk, SOL_IPV6, IPV6_V6ONLY, &v6only, sizeof(v6only)) < 0) {
1343                 connman_error("Failed to clear V6ONLY on %s listener socket",
1344                               proto);
1345                 close(sk);
1346                 return -EIO;
1347         }
1348
1349         if (family == AF_INET) {
1350                 memset(&s.sin, 0, sizeof(s.sin));
1351                 s.sin.sin_family = AF_INET;
1352                 s.sin.sin_port = htons(53);
1353                 s.sin.sin_addr.s_addr = htonl(INADDR_ANY);
1354                 slen = sizeof(s.sin);
1355         } else {
1356                 memset(&s.sin6, 0, sizeof(s.sin6));
1357                 s.sin6.sin6_family = AF_INET6;
1358                 s.sin6.sin6_port = htons(53);
1359                 s.sin6.sin6_addr = in6addr_any;
1360                 slen = sizeof(s.sin6);
1361         }
1362
1363         if (bind(sk, &s.sa, slen) < 0) {
1364                 connman_error("Failed to bind %s listener socket", proto);
1365                 close(sk);
1366                 return -EIO;
1367         }
1368
1369         if (protocol == IPPROTO_TCP && listen(sk, 10) < 0) {
1370                 connman_error("Failed to listen on TCP socket");
1371                 close(sk);
1372                 return -EIO;
1373         }
1374
1375         channel = g_io_channel_unix_new(sk);
1376         if (channel == NULL) {
1377                 connman_error("Failed to create %s listener channel", proto);
1378                 close(sk);
1379                 return -EIO;
1380         }
1381
1382         g_io_channel_set_close_on_unref(channel, TRUE);
1383
1384         if (protocol == IPPROTO_TCP) {
1385                 tcp_listener_channel = channel;
1386                 tcp_listener_watch = g_io_add_watch(channel,
1387                                         G_IO_IN, tcp_listener_event, NULL);
1388         } else {
1389                 udp_listener_channel = channel;
1390                 udp_listener_watch = g_io_add_watch(channel,
1391                                         G_IO_IN, udp_listener_event, NULL);
1392         }
1393
1394         return 0;
1395 }
1396
1397 static void destroy_udp_listener(void)
1398 {
1399         DBG("");
1400
1401         if (udp_listener_watch > 0)
1402                 g_source_remove(udp_listener_watch);
1403
1404         g_io_channel_unref(udp_listener_channel);
1405 }
1406
1407 static void destroy_tcp_listener(void)
1408 {
1409         DBG("");
1410
1411         if (tcp_listener_watch > 0)
1412                 g_source_remove(tcp_listener_watch);
1413
1414         g_io_channel_unref(tcp_listener_channel);
1415 }
1416
1417 static int create_listener(void)
1418 {
1419         int err;
1420
1421         err = create_dns_listener(IPPROTO_UDP);
1422         if (err < 0)
1423                 return err;
1424
1425         err = create_dns_listener(IPPROTO_TCP);
1426         if (err < 0) {
1427                 destroy_udp_listener();
1428                 return err;
1429         }
1430
1431         connman_resolver_append("lo", NULL, "127.0.0.1");
1432
1433         return 0;
1434 }
1435
1436 static void destroy_listener(void)
1437 {
1438         GSList *list;
1439
1440         connman_resolver_remove_all("lo");
1441
1442         for (list = request_pending_list; list; list = list->next) {
1443                 struct request_data *req = list->data;
1444
1445                 DBG("Dropping pending request (id 0x%04x -> 0x%04x)",
1446                                                 req->srcid, req->dstid);
1447
1448                 g_free(req->resp);
1449                 g_free(req->request);
1450                 g_free(req->name);
1451                 g_free(req);
1452                 list->data = NULL;
1453         }
1454
1455         g_slist_free(request_pending_list);
1456         request_pending_list = NULL;
1457
1458         for (list = request_list; list; list = list->next) {
1459                 struct request_data *req = list->data;
1460
1461                 DBG("Dropping request (id 0x%04x -> 0x%04x)",
1462                                                 req->srcid, req->dstid);
1463
1464                 g_free(req->resp);
1465                 g_free(req->request);
1466                 g_free(req->name);
1467                 g_free(req);
1468                 list->data = NULL;
1469         }
1470
1471         g_slist_free(request_list);
1472         request_list = NULL;
1473
1474         destroy_tcp_listener();
1475         destroy_udp_listener();
1476 }
1477
1478 int __connman_dnsproxy_init(void)
1479 {
1480         int err;
1481
1482         err = create_listener();
1483         if (err < 0)
1484                 return err;
1485
1486         err = connman_resolver_register(&dnsproxy_resolver);
1487         if (err < 0)
1488                 goto destroy;
1489
1490         err = connman_notifier_register(&dnsproxy_notifier);
1491         if (err < 0)
1492                 goto unregister;
1493
1494         return 0;
1495
1496 unregister:
1497         connman_resolver_unregister(&dnsproxy_resolver);
1498
1499 destroy:
1500         destroy_listener();
1501
1502         return err;
1503 }
1504
1505 void __connman_dnsproxy_cleanup(void)
1506 {
1507         connman_notifier_unregister(&dnsproxy_notifier);
1508
1509         connman_resolver_unregister(&dnsproxy_resolver);
1510
1511         destroy_listener();
1512 }